FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5038

This CVE name corresponds to:

Entered Topic
2007-09-20 bugzilla -- "createmailregexp" security bypass vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5038
Phase Assigned(20070923)

Description

The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.

References

Source Reference
BUGTRAQ 20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1
CONFIRM http://www.bugzilla.org/security/3.0.1/
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=395632
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=299981
FEDORA FEDORA-2007-2299
BID 25725
VUPEN ADV-2007-3200
SECTRACK 1018719
SECUNIA 26848
SECUNIA 26969
XF bugzilla-offeraccount-security-bypass(36692)